Loading market data...
← Back to CVE feed

CVE-2026-89238

CRITICAL CVSS 9.1 View on NVD ↗

Description

WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Published: Sep 30, 2026 13:17 UTC Modified: Sep 30, 2026 20:17 UTC